DNS activity - BlueCat Edge - Service Point v4.x.x

BlueCat Edge User Guide

Locale
English
Product name
BlueCat Edge
Version
Service Point v4.x.x

The DNS activity screen displays DNS queries from the configured sites. Available information includes the date and time of the query, the source and site, the query name and type, the response, and policy action (block, trust, or monitor) that was taken. You can filter the DNS activity list by time, sites, site groups, and other criteria.

Viewing DNS activity

  1. In the BlueCat Edge window, click .
  2. Select the DNS Activity tab. For more information about viewing threat activity tab, see Identifying threat activity.
  3. Click to refresh the DNS queries list.
  4. Use the filter icons or the following filter commands to search for DNS queries by the following criteria:
    • date & time
    • latency
    • site
    • source IP
    • query type
    • query name
    • protocol
    • response code
    • response IP
    • policy name
    • policy action
    • namespace
    • threat type
    • threat indicator
    • user ID

    Criteria can be combined, and BlueCat Edge will only return queries when all of the specified conditions are met.

    Examples

    /sitename TorontoSite /from 08-17-2017 00:00:00 /to 08-17-2017 04:00:00

    /at 03-17-2017 22:30:00 /sitename GlasgowSite

    When you enter the filter command, the results display and the text in the command bar turns green. Results remain filtered until you begin typing another command.

  5. Click to add another tab. In the Add Tab window, select the available columns on the left, then click Add Tab. You must enter a name for the tab in the Title field. You can add multiple columns to the tab, and click and drag a selected column on the right to re-order the columns. To delete the tab, click the delete button beside the tab name.
    Note: The Date & Time column is selected by default.
  6. Click to select the columns you want displayed in the tab. In the Update Tab window, select the available columns on the left, then click Update Tab. You can click and drag a selected column on the right to re-order the columns. To restore the default columns and order, click Restore Defaults.

  7. To view detailed information about a DNS query, click the query.

    In the DNS query information panel, you can click links to view sites, namespaces, policies, and (for Vol Tunnel threat indicators) system lists associated with the query. When you click a link, a new tab opens in the panel, allowing you to return to the query information easily.

    Click next to different fields to filter the DNS activity results based on the value of that field.

    Click Inspect Client Activity to retrieve additional query information from the source IP of the current query. For more information, refer to Client activity.

  8. Click to download a CSV file containing detailed query log information about the DNS Activity based on the selected filters. The CSV file contains up to 10,000 queries.
    Note: If a query contains multiple Answer and Authority records, only the first five of each record are returned. However, the CSV file displays the total count of Answer and Authority records for each query.
  9. To return to the map view, click .

Filter command tips

  • Enter times in 24-hour format (HH:MM:SS). All digits are required.
  • Enter dates in MM-DD-YYYY format (03-15-2023). All digits are required.
  • You can copy a list of filter values and paste them to text filter command bar.

    For example:

    If you copy the following list for the /queryname filter command:

    abc.com

    meow.com

    ham.com

    Then paste them to the text filter command bar, the list of items will display as comma separated:

  • If you enter the incorrect filter commands and values, a list of errors will display below the text filter command bar..

  • Filters become active when you press Enter and remain active until you change the text in the command bar. Active filters are indicated by green text in the command bar.
  • Click to view the filter history. You can delete and pin items in the list.
    Note: You can pin up to 10 items in the list.

  • You can copy the URL of a filter by clicking , then right-clicking the filter > Copy Link Address. You can also copy the URL in the URL field of your browser.
  • You can extend your search for more than one item at a time by adding multiple items, separated by commas. For example:

    /policyaction block, redirect

    Note: The extended search is only available for the following filters:
    • /site
    • /source
    • /querytype
    • /queryname
    • /protocol
    • /namespace
    • /response
    • /policyname
    • /policyaction
    • /threattype
    • /threatind
  • You can use one or more filters at a time on the command line. For example, you can combine filters for date/time, policy action, and site name.
  • Using the BlueCat Edge dashboard, you can select a time range on the graph to filter DNS queries in the DNS Activity window. You can deselect one or more policy actions to filter both by the selected time range, and the visible policy actions.

    dashboard select time range